100% Process, taskmgr.exe, PC sluggish
gwen82
Posted messages
13
Status
Membre
-
Fab -
Fab -
Hello!
For several days now, I've been dealing with my PC running extremely slowly.
Upon startup, it takes between 10 and 15 minutes to boot up.
And then, it's practically impossible for me to do anything as I have to wait 5 minutes for a simple click to take effect (not to mention launching a software).
However, here’s what I see when I manage to open the task manager:
- processes constantly using 100% (it fluctuates between 95 and 100%)
- TASKMGR.EXE between 50 and 75% (when it's not 90%)
- EXPLORER.EXE and SERVICES.EXE occupying the remaining % 15 to 20%
I know that taskmgr.exe corresponds to the task manager, but whether it is closed or not doesn't change anything, the PC still runs slow.
I tried replacing it with ProcessExplorer, but it shows the same kind of results as TASKMGR.EXE (namely PROCESSEXPLORER.exe at 50-70%, EXPLORER.EXE and SERVICES.EXE at 15-20%
However, sometimes my PC starts normally. Unfortunately, this only happens once a week, even though I try starting it 1 or 2 times a day just to see if I can use it (essentially, it starts correctly about 1 in 10 times).
When it does start normally, I take the opportunity to perform some cleanup like online anti-spyware scans (PandaActiveScan, Secuser, ...) which have removed a few infections but haven't solved the problem.
I also replaced my outdated NortonAntiVirus with AvastAntiVirus, which I have obviously launched, but it found nothing on the PC.
Note: As for deleting temporary files, emptying the recycle bin, disk cleanup, and defragmentation, I execute these regularly (1 or 2 times a week).
After several attempts to eliminate potential infections, I decided to completely format my hard drive, which I did this weekend.
On Saturday, I took care of reinstalling Windows XP, and then recovering some software downloaded from the internet, namely Avast antivirus and the ZoneAlarm firewall (which I also used before).
After rebooting, I quickly updated Windows with WindowsUpdate, then rebooted, followed by updating Windows with the installation of the SP2 pack, then rebooting again, and finally the last updates with WindowsUpdate.
It’s 2 AM and I decide to stop there for the night...
And the next day, when I start my PC, what do I see? I'm back with exactly the same problem I had before my format, with a process at 100%!!!
At this point, I admit I don't understand because the PC is completely empty, with no programs (except the antivirus, firewall, and Windows updates) and none of my documents.
So, I wonder if it’s possible that my hardware has become faulty.
I hope that with all this information, you can give me some interesting leads to resolve my issue. Thank you. Best regards.
Gwen
Configuration: Windows XP SP2
Internet Explorer 7.0
AMD Sempron 2400+
512Mb RAM
For several days now, I've been dealing with my PC running extremely slowly.
Upon startup, it takes between 10 and 15 minutes to boot up.
And then, it's practically impossible for me to do anything as I have to wait 5 minutes for a simple click to take effect (not to mention launching a software).
However, here’s what I see when I manage to open the task manager:
- processes constantly using 100% (it fluctuates between 95 and 100%)
- TASKMGR.EXE between 50 and 75% (when it's not 90%)
- EXPLORER.EXE and SERVICES.EXE occupying the remaining % 15 to 20%
I know that taskmgr.exe corresponds to the task manager, but whether it is closed or not doesn't change anything, the PC still runs slow.
I tried replacing it with ProcessExplorer, but it shows the same kind of results as TASKMGR.EXE (namely PROCESSEXPLORER.exe at 50-70%, EXPLORER.EXE and SERVICES.EXE at 15-20%
However, sometimes my PC starts normally. Unfortunately, this only happens once a week, even though I try starting it 1 or 2 times a day just to see if I can use it (essentially, it starts correctly about 1 in 10 times).
When it does start normally, I take the opportunity to perform some cleanup like online anti-spyware scans (PandaActiveScan, Secuser, ...) which have removed a few infections but haven't solved the problem.
I also replaced my outdated NortonAntiVirus with AvastAntiVirus, which I have obviously launched, but it found nothing on the PC.
Note: As for deleting temporary files, emptying the recycle bin, disk cleanup, and defragmentation, I execute these regularly (1 or 2 times a week).
After several attempts to eliminate potential infections, I decided to completely format my hard drive, which I did this weekend.
On Saturday, I took care of reinstalling Windows XP, and then recovering some software downloaded from the internet, namely Avast antivirus and the ZoneAlarm firewall (which I also used before).
After rebooting, I quickly updated Windows with WindowsUpdate, then rebooted, followed by updating Windows with the installation of the SP2 pack, then rebooting again, and finally the last updates with WindowsUpdate.
It’s 2 AM and I decide to stop there for the night...
And the next day, when I start my PC, what do I see? I'm back with exactly the same problem I had before my format, with a process at 100%!!!
At this point, I admit I don't understand because the PC is completely empty, with no programs (except the antivirus, firewall, and Windows updates) and none of my documents.
So, I wonder if it’s possible that my hardware has become faulty.
I hope that with all this information, you can give me some interesting leads to resolve my issue. Thank you. Best regards.
Gwen
Configuration: Windows XP SP2
Internet Explorer 7.0
AMD Sempron 2400+
512Mb RAM
Configuration: Windows XP SP2 Internet Explorer 7.0 30GB HDD / 250MB RAM / Intel Celeron 2.4GHz / Samsung laptop
18 réponses
First of all, hello and welcome to the HELP forum HOW IT WORKS
We understand your situation and we advise you not to worry at all.
Moreover, given the increasing number of disinfections being carried out on the forum, we ask for your patience and especially not to create multiple threads for the same problem.
Thank you for your understanding.
Download HijackThis here:
http://www.merijn.org/files/hijackthis.zip
or here:
https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/29061.html
Unzip it into a designated folder.
For example, C:\hijackthis < Make sure to save it in c: !
Demo: (Thanks to Balltrap34 for this creation)
http://perso.orange.fr/rginformatique/section%20virus/Hijenr.gif
Run it then:
click on "do a system scan and save logfile" (see demo)
copy and paste the entire log on the forum
Demo: (Thanks to Balltrap34 for this creation)
http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm
Good luck
See you+
We understand your situation and we advise you not to worry at all.
Moreover, given the increasing number of disinfections being carried out on the forum, we ask for your patience and especially not to create multiple threads for the same problem.
Thank you for your understanding.
Download HijackThis here:
http://www.merijn.org/files/hijackthis.zip
or here:
https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/29061.html
Unzip it into a designated folder.
For example, C:\hijackthis < Make sure to save it in c: !
Demo: (Thanks to Balltrap34 for this creation)
http://perso.orange.fr/rginformatique/section%20virus/Hijenr.gif
Run it then:
click on "do a system scan and save logfile" (see demo)
copy and paste the entire log on the forum
Demo: (Thanks to Balltrap34 for this creation)
http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm
Good luck
See you+
BILAN DU FIL DE DISCUSSION : PROBLEME RESOLU
PROBLEME rencontré :- PC qui rame avec un UC utilisé à 100% par les processus (notamment 'taskmgr.exe')
(protection utilisée ZoneAlarm7.0+ AvastAntiVirus4.7)
Pistes explorées :- Utilisation de plusieurs antivirus / antispywares en ligne (mais sans résultats concernant le bug)
- Remplacement du "GestionnaireDesTaches" par "ProcessExplorer", mais sans résultats.
- Formatage de Windows XP SP2, malheureusement je me retrouve avec le même problème.
SOLUTION proposée par CommentCaMarche :- Désinstallation du PareFeu ZoneAlarm, et installation de Kerios à la place.
la cause du problème :
Problème de compatibilité à propos du filtrage web entre ZoneAlarm et AvastAntiVirus car ZA est un firewall, mais qui possède aussi des fonctions de filtrage web et antivirus.
Avast est un antivirus, mais il possède également des fonctions de filtrage web.
Il ne faut donc pas que ZA et Avast fassent la même chose en même temps (risques de conflits, plantage, erreurs de filtrage).
REMERCIEMENT :
Sincères remerciements à Duflox, (CommenCaMarche) pour ses réponses rapide et explicites (problème résolu en 48h)
PROBLEME rencontré :- PC qui rame avec un UC utilisé à 100% par les processus (notamment 'taskmgr.exe')
(protection utilisée ZoneAlarm7.0+ AvastAntiVirus4.7)
Pistes explorées :- Utilisation de plusieurs antivirus / antispywares en ligne (mais sans résultats concernant le bug)
- Remplacement du "GestionnaireDesTaches" par "ProcessExplorer", mais sans résultats.
- Formatage de Windows XP SP2, malheureusement je me retrouve avec le même problème.
SOLUTION proposée par CommentCaMarche :- Désinstallation du PareFeu ZoneAlarm, et installation de Kerios à la place.
la cause du problème :
Problème de compatibilité à propos du filtrage web entre ZoneAlarm et AvastAntiVirus car ZA est un firewall, mais qui possède aussi des fonctions de filtrage web et antivirus.
Avast est un antivirus, mais il possède également des fonctions de filtrage web.
Il ne faut donc pas que ZA et Avast fassent la même chose en même temps (risques de conflits, plantage, erreurs de filtrage).
REMERCIEMENT :
Sincères remerciements à Duflox, (CommenCaMarche) pour ses réponses rapide et explicites (problème résolu en 48h)
Thank you for your support and for your quick response.
I will run "hijackthis" as soon as possible and will post the results shortly.
Best regards,
Gwen
I will run "hijackthis" as soon as possible and will post the results shortly.
Best regards,
Gwen
Good evening,
Back home, I found my mobile which started up without any problems (for once ;-)
So I was able to quickly run HijackThis on the PC, and here are the results it gave me:
(Note that after my XP reinstall, I've already performed a system restore thinking I resolved the issue, I only undid the last Windows Update updates right after the SP2 pack)
-------------------------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 23:11:36, on 15/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gocyberlink.com/registration/registration1.asp?SoftWare=POWERDVD&Version_Num=4.0&Cd_Key=MV37751753212355&Company=Gwenael&FName=MICHEL&Lang=Fra
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Wireless-G Notebook Adapter.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
O8 - Extra context menu item: &Download with NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: Download all wit&h NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: iPod Service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
-------------------------------------------------------------------------------------------
Good luck decoding all this!
Gwen
Back home, I found my mobile which started up without any problems (for once ;-)
So I was able to quickly run HijackThis on the PC, and here are the results it gave me:
(Note that after my XP reinstall, I've already performed a system restore thinking I resolved the issue, I only undid the last Windows Update updates right after the SP2 pack)
-------------------------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 23:11:36, on 15/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gocyberlink.com/registration/registration1.asp?SoftWare=POWERDVD&Version_Num=4.0&Cd_Key=MV37751753212355&Company=Gwenael&FName=MICHEL&Lang=Fra
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Wireless-G Notebook Adapter.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
O8 - Extra context menu item: &Download with NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: Download all wit&h NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: iPod Service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
-------------------------------------------------------------------------------------------
Good luck decoding all this!
Gwen
just a little information:
When you install Avast after ZoneAlarm, you must have seen a warning window regarding a compatibility issue about web filtering.
ZA is a firewall, but it also has web filtering and antivirus functions.
Avast is an antivirus, but it also has web filtering functions.
Therefore, ZA and Avast should not perform the same function at the same time (risk of conflicts, crashes, filtering errors).
So, I recommend disabling all ZA functions except the firewall function (since that's the primary goal). (So disable the antivirus, web filter, etc. functions of ZA.)
In this way, you will be very well protected, and there will be no conflict between the two (Successfully tested for several months under Windows 98 and Windows XP SP2).
As always with ZA, it is important to disable the built-in firewall in Windows XP SP2.
Have you configured it like this?
When you install Avast after ZoneAlarm, you must have seen a warning window regarding a compatibility issue about web filtering.
ZA is a firewall, but it also has web filtering and antivirus functions.
Avast is an antivirus, but it also has web filtering functions.
Therefore, ZA and Avast should not perform the same function at the same time (risk of conflicts, crashes, filtering errors).
So, I recommend disabling all ZA functions except the firewall function (since that's the primary goal). (So disable the antivirus, web filter, etc. functions of ZA.)
In this way, you will be very well protected, and there will be no conflict between the two (Successfully tested for several months under Windows 98 and Windows XP SP2).
As always with ZA, it is important to disable the built-in firewall in Windows XP SP2.
Have you configured it like this?
Hello,
I am also sending you the result of HijackThis while the PC is running with all the symptoms described above (and it's not easy, especially since it goes into sleep mode every 2-3 minutes)
I wasn't really able to check if there were any differences between the two results, and I apologize for that.
NB: The previous result was made while the PC was running (apparently well)
Logfile of HijackThis v1.99.1
Scan saved at 20:45:29, on 16/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gocyberlink.com/registration/registration1.asp?SoftWare=POWERDVD&Version_Num=4.0&Cd_Key=MV37751753212355&Company=Gwenael&FName=MICHEL&Lang=Fra
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Wireless-G Notebook Adapter.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
O8 - Extra context menu item: &Télécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: Tout t&élécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Thank you for your help,
Gwen
-------------------------------------------------------------------------------------------
- I just read your response, but I don't see how to disable the web filtering and antivirus functions of ZA, I can only find an antivirus monitoring function.
- Regarding the Windows XP SP2 firewall, yes it is indeed disabled.
- However, I would like to re-emphasize a small thing that may be important:
Before Avast AntiVirus (which I installed since the formatting last weekend), I had been using Norton AntiVirus for several years alongside ZoneAlarm, and I had never had any particular issues (but it's true that the version of Norton 2002 that I was using had become obsolete since it could no longer retrieve the latest updates)
I am also sending you the result of HijackThis while the PC is running with all the symptoms described above (and it's not easy, especially since it goes into sleep mode every 2-3 minutes)
I wasn't really able to check if there were any differences between the two results, and I apologize for that.
NB: The previous result was made while the PC was running (apparently well)
Logfile of HijackThis v1.99.1
Scan saved at 20:45:29, on 16/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gocyberlink.com/registration/registration1.asp?SoftWare=POWERDVD&Version_Num=4.0&Cd_Key=MV37751753212355&Company=Gwenael&FName=MICHEL&Lang=Fra
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Wireless-G Notebook Adapter.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
O8 - Extra context menu item: &Télécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: Tout t&élécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Thank you for your help,
Gwen
-------------------------------------------------------------------------------------------
- I just read your response, but I don't see how to disable the web filtering and antivirus functions of ZA, I can only find an antivirus monitoring function.
- Regarding the Windows XP SP2 firewall, yes it is indeed disabled.
- However, I would like to re-emphasize a small thing that may be important:
Before Avast AntiVirus (which I installed since the formatting last weekend), I had been using Norton AntiVirus for several years alongside ZoneAlarm, and I had never had any particular issues (but it's true that the version of Norton 2002 that I was using had become obsolete since it could no longer retrieve the latest updates)
Okay, if you can't find how to do it, uninstall ZA and install Kerio!!
Kerio and Avast are no problem!!
Kerio (firewall): remains free after the trial period in French
----> http://www.infos-du-net.com/telecharger/Firewall-Kerio-Personal,0301-390.html
Check out this tutorial if you need help with the installation, configuration, and understanding of Kerio
http://www.malekal.com/kerio_firewall.php
More info:
->https://kerio.probb.fr/
Kerio and Avast are no problem!!
Kerio (firewall): remains free after the trial period in French
----> http://www.infos-du-net.com/telecharger/Firewall-Kerio-Personal,0301-390.html
Check out this tutorial if you need help with the installation, configuration, and understanding of Kerio
http://www.malekal.com/kerio_firewall.php
More info:
->https://kerio.probb.fr/
Following your message regarding ZA, I have disabled the Basic MailSafe email protection, and apparently everything is working today. I’m still wary of this state of affairs (is it temporary or for good)
Otherwise, the installed version of ZA is 7.0.362.000 (apparently no antivirus functions, web filter).
If I encounter the same problem again, I will likely switch to Kerio (it's a shame because I really liked Zone Alarm), but if it helps me avoid these issues.
In any case, I sincerely thank you for your quick, clear, and explicit responses.
Regards,
Gwen
Otherwise, the installed version of ZA is 7.0.362.000 (apparently no antivirus functions, web filter).
If I encounter the same problem again, I will likely switch to Kerio (it's a shame because I really liked Zone Alarm), but if it helps me avoid these issues.
In any case, I sincerely thank you for your quick, clear, and explicit responses.
Regards,
Gwen
Hello,
On Friday, I performed the operations you advised me (specifically uninstalling ZA to replace it with Kerio).
On Saturday, I was able to use the PC without any issues. But unfortunately, this morning (Sunday), my PC is slow again!
(I also updated with Windows Update).
Apparently, replacing the firewall is not enough to fix the problem.
Could you please take another look at the HijackThis result from this morning?
PS: In addition to the PC being slow, it is now going to sleep (after 30 seconds to 5 minutes of use).
And it seems that Kerio has not started (no icon at the bottom right of the screen)
Good luck,
Gwen
-------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 12:23:52, on 19/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.gocyberlink.com/registration/registration1.asp?SoftWare=POWERDVD&Version_Num=4.0&Cd_Key=MV37751753212355&Company=Gwenael&FName=MICHEL&Lang=Fra
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Quick Launch of Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Wireless-G Notebook Adapter.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
O8 - Extra context menu item: &Download with NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: Download everything with NetTransport -
C:\Program Files\Xi\NetTransport 2\NTAddList.html
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} -
C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} -
C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -
C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
On Friday, I performed the operations you advised me (specifically uninstalling ZA to replace it with Kerio).
On Saturday, I was able to use the PC without any issues. But unfortunately, this morning (Sunday), my PC is slow again!
(I also updated with Windows Update).
Apparently, replacing the firewall is not enough to fix the problem.
Could you please take another look at the HijackThis result from this morning?
PS: In addition to the PC being slow, it is now going to sleep (after 30 seconds to 5 minutes of use).
And it seems that Kerio has not started (no icon at the bottom right of the screen)
Good luck,
Gwen
-------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 12:23:52, on 19/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.gocyberlink.com/registration/registration1.asp?SoftWare=POWERDVD&Version_Num=4.0&Cd_Key=MV37751753212355&Company=Gwenael&FName=MICHEL&Lang=Fra
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Quick Launch of Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Wireless-G Notebook Adapter.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
O8 - Extra context menu item: &Download with NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: Download everything with NetTransport -
C:\Program Files\Xi\NetTransport 2\NTAddList.html
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} -
C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} -
C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -
C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
Ok, let's try to solve this problem!!
* Download AVG Anti-Spyware
avg antispyware
http://www.infos-du-net.com/telecharger/Ewido-Security-Suite,0301-734.html
Tutorial: http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html
* Install it
Start AVG antispyware. Click on "update", click on the button "Start update" and wait for this update to finish, then close the program.
If you can't update it, get the updates here:
http://downloads.ewido.net/avgas-signatures-full-current.exe
Start in safe mode:
To do this, tap the F8 key as soon as you start the pc without stopping
A window will open, move with the arrow keys to start in safe mode and then press enter.
Once on the desktop, if there are no colors and others, it's normal!
(If F8 doesn't work, use the F5 key).
Restart AVG AS and click on the "scanner" tab, then on "Full system scan".
Once the scan is complete, it will display a report. Click on "configure..." at the bottom left and choose "delete". Then click on "Apply all actions", this will remove all detected infections.
Then click on "Save scan report" -> "save as" and save the report wherever you like, so that you can send it to me in your next reply.
Copy and paste the report here.
* Download AVG Anti-Spyware
avg antispyware
http://www.infos-du-net.com/telecharger/Ewido-Security-Suite,0301-734.html
Tutorial: http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html
* Install it
Start AVG antispyware. Click on "update", click on the button "Start update" and wait for this update to finish, then close the program.
If you can't update it, get the updates here:
http://downloads.ewido.net/avgas-signatures-full-current.exe
Start in safe mode:
To do this, tap the F8 key as soon as you start the pc without stopping
A window will open, move with the arrow keys to start in safe mode and then press enter.
Once on the desktop, if there are no colors and others, it's normal!
(If F8 doesn't work, use the F5 key).
Restart AVG AS and click on the "scanner" tab, then on "Full system scan".
Once the scan is complete, it will display a report. Click on "configure..." at the bottom left and choose "delete". Then click on "Apply all actions", this will remove all detected infections.
Then click on "Save scan report" -> "save as" and save the report wherever you like, so that you can send it to me in your next reply.
Copy and paste the report here.
Good evening,
I had to restart my PC 3 or 4 times today with the usual processes at 100% and frequent sleep modes.
Curiously, the last startup had all the usual symptoms, except that for the first time, it returned to normal after 10-15 minutes!
I was able to quickly recover AVG Anti-Spyware and update it, then I restarted the computer in safe mode.
It has just finished the full scan, and I'm posting its result below.
In my opinion, this doesn't indicate anything serious since it only found 34 cookies!
See you later
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 20:27:59 19/08/2007
+ Scan result:
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@notrefamille.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@mistergooddeal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@msnaccountservices.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@www.adobe[2].txt -> TrackingCookie.Adobe : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@ads.cnn[1].txt -> TrackingCookie.Cnn : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@dm.com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@fl01.ct2.comclick[1].txt -> TrackingCookie.Comclick : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@estat[1].txt -> TrackingCookie.Estat : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Local Settings\Temp\Cookies\gwenael_michel@estat[1].txt -> TrackingCookie.Estat : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@search.live[1].txt -> TrackingCookie.Live : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@data3.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@real[1].txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@smartadserver[2].txt -> TrackingCookie.Smartadserver : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@weborama[1].txt -> TrackingCookie.Weborama : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Local Settings\Temp\Cookies\gwenael_michel@weborama[2].txt -> TrackingCookie.Weborama : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@m.webtrends[2].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Cleaned.
End of report
I had to restart my PC 3 or 4 times today with the usual processes at 100% and frequent sleep modes.
Curiously, the last startup had all the usual symptoms, except that for the first time, it returned to normal after 10-15 minutes!
I was able to quickly recover AVG Anti-Spyware and update it, then I restarted the computer in safe mode.
It has just finished the full scan, and I'm posting its result below.
In my opinion, this doesn't indicate anything serious since it only found 34 cookies!
See you later
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 20:27:59 19/08/2007
+ Scan result:
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@notrefamille.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@mistergooddeal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@msnaccountservices.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@www.adobe[2].txt -> TrackingCookie.Adobe : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@ads.cnn[1].txt -> TrackingCookie.Cnn : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@dm.com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@fl01.ct2.comclick[1].txt -> TrackingCookie.Comclick : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@estat[1].txt -> TrackingCookie.Estat : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Local Settings\Temp\Cookies\gwenael_michel@estat[1].txt -> TrackingCookie.Estat : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@search.live[1].txt -> TrackingCookie.Live : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@data3.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael michel@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@real[1].txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@smartadserver[2].txt -> TrackingCookie.Smartadserver : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@weborama[1].txt -> TrackingCookie.Weborama : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Local Settings\Temp\Cookies\gwenael_michel@weborama[2].txt -> TrackingCookie.Weborama : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@m.webtrends[2].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Gwenael MICHEL\Cookies\gwenael_michel@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Cleaned.
End of report
Open this link (thanks to S!RI for this program). http://siri.urz.free.fr/Fix/SmitfraudFix.php
and download SmitfraudFix.exe.
Watch the tutorial
Run it by choosing option 1, it will generate a report
Please copy/paste it on the post.
and download SmitfraudFix.exe.
Watch the tutorial
Run it by choosing option 1, it will generate a report
Please copy/paste it on the post.
Hello,
Here is the report from SmitFraudFix.exe
Otherwise, the PC starts correctly 1 time out of 2 (instead of 1 time out of 10), but I would have preferred it to be every time ;-)
See you later
----------------------------------------------------------------------------------------------------------
SmitFraudFix v2.214
Report made at 20:29:54.97, 23/08/2007
Executed from C:\Documents and Settings\Gwenael MICHEL\Desktop\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
The file system type is NTFS
Fix executed in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Gwenael MICHEL
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Gwenael MICHEL\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\GWENAE~1\Favorites
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop items
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My homepage"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Warning, the keys that follow may not necessarily be infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Warning, the keys that follow may not necessarily be infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Warning, the keys that follow may not necessarily be infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Wireless-G Notebook Adapter WPC54G V3 - Packet scheduling miniport
DNS Server Search Order: 192.168.1.254
HKLM\SYSTEM\CCS\Services\Tcpip\..\{A73ECF66-C54F-4F7C-A869-896AA77368A5}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS1\Services\Tcpip\..\{A73ECF66-C54F-4F7C-A869-896AA77368A5}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
»»»»»»»»»»»»»»»»»»»»»»»» Search for wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End
Here is the report from SmitFraudFix.exe
Otherwise, the PC starts correctly 1 time out of 2 (instead of 1 time out of 10), but I would have preferred it to be every time ;-)
See you later
----------------------------------------------------------------------------------------------------------
SmitFraudFix v2.214
Report made at 20:29:54.97, 23/08/2007
Executed from C:\Documents and Settings\Gwenael MICHEL\Desktop\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
The file system type is NTFS
Fix executed in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Gwenael MICHEL
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Gwenael MICHEL\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\GWENAE~1\Favorites
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop items
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My homepage"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Warning, the keys that follow may not necessarily be infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Warning, the keys that follow may not necessarily be infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Warning, the keys that follow may not necessarily be infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Wireless-G Notebook Adapter WPC54G V3 - Packet scheduling miniport
DNS Server Search Order: 192.168.1.254
HKLM\SYSTEM\CCS\Services\Tcpip\..\{A73ECF66-C54F-4F7C-A869-896AA77368A5}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS1\Services\Tcpip\..\{A73ECF66-C54F-4F7C-A869-896AA77368A5}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
»»»»»»»»»»»»»»»»»»»»»»»» Search for wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End
scan here
https://www.bitdefender.com/
* At the bottom left of the window, click on BitDefender SCAN ONLINE
* In the new window, click on I accept
* Accept the Active X control and install it. The scanner loads
* The window changes again, click on 'click here to scan'
* The signatures are loading, etc.
image tutorial:
http://pageperso.aol.fr/rginformatique/mapage/defender.htm
copy and paste the result here
https://www.bitdefender.com/
* At the bottom left of the window, click on BitDefender SCAN ONLINE
* In the new window, click on I accept
* Accept the Active X control and install it. The scanner loads
* The window changes again, click on 'click here to scan'
* The signatures are loading, etc.
image tutorial:
http://pageperso.aol.fr/rginformatique/mapage/defender.htm
copy and paste the result here
Below is the result of the BitDefender Online Scanner analysis (it seems nothing serious) ...
-----------------------------------------------------------------------------------------------------------------------
BitDefender Online Scanner
Analysis report generated on: Fri, Aug 24, 2007 - 15:59:26
Scan path: C:\;D:\;
Statistics
Time
01:24:40
Files
83760
Directories
3381
Boot sectors
2
Archives
1256
Program packages
4670
Results
Viruses identified
0
Infected files
0
Suspicious files
0
Warnings
0
Disinfected
0
Deleted files
0
Info on the engines
Virus definition
749820
Engine versions
AVCORE v1.0 (build 2411) (i386) (Jul 9 2007 12:10:22)
Plugin analysis
14
Plugin archive
37
Plugin unpack
6
Email plugins
6
System plugins
1
Scan settings
First action
Disinfected
Second action
Deleted
Heuristic
Yes
Accept warnings
Yes
Analyzed extensions
*;
Exclude extensions
Email analysis
Yes
Archive analysis
Yes
Analyze program packages
Yes
File analysis
Yes
Boot analysis
Yes
File analyzed
Status
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>Acknowledgements.rtf
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iTunesAdmin.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iTunesPhotoSupport.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iTunesHelper.exe
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iTunesMiniPlayer.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iTunesOutlookAddIn.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodUpdaterExt.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>CDDBControlApple.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>gcdrdll.cfg
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>gcdroem.cfg
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>gcdrtype.cfg
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodAcknowledgements.rtf
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.exe
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>npitunes.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>npitunes.xpt
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>itms.js
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_iPodService.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_da.lproj_iPodServiceLocalized.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_de.lproj_iPodServiceLocalized.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_en.lproj_iPodServiceLocalized.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_es.lproj_iPodServiceLocalized.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_fi.lproj_iPodServiceLocalized.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_fr.lproj_iPodServiceLocalized.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_it.lproj_iPodServiceLocalized.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_ja.lproj_iPodServiceLocalized.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_ko.lproj_iPodServiceLocalized.dll
Cleaned
-----------------------------------------------------------------------------------------------------------------------
BitDefender Online Scanner
Analysis report generated on: Fri, Aug 24, 2007 - 15:59:26
Scan path: C:\;D:\;
Statistics
Time
01:24:40
Files
83760
Directories
3381
Boot sectors
2
Archives
1256
Program packages
4670
Results
Viruses identified
0
Infected files
0
Suspicious files
0
Warnings
0
Disinfected
0
Deleted files
0
Info on the engines
Virus definition
749820
Engine versions
AVCORE v1.0 (build 2411) (i386) (Jul 9 2007 12:10:22)
Plugin analysis
14
Plugin archive
37
Plugin unpack
6
Email plugins
6
System plugins
1
Scan settings
First action
Disinfected
Second action
Deleted
Heuristic
Yes
Accept warnings
Yes
Analyzed extensions
*;
Exclude extensions
Email analysis
Yes
Archive analysis
Yes
Analyze program packages
Yes
File analysis
Yes
Boot analysis
Yes
File analyzed
Status
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>Acknowledgements.rtf
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iTunesAdmin.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iTunesPhotoSupport.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iTunesHelper.exe
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iTunesMiniPlayer.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iTunesOutlookAddIn.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodUpdaterExt.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>CDDBControlApple.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>gcdrdll.cfg
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>gcdroem.cfg
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>gcdrtype.cfg
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodAcknowledgements.rtf
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.exe
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>npitunes.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>npitunes.xpt
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>itms.js
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_iPodService.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_da.lproj_iPodServiceLocalized.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_de.lproj_iPodServiceLocalized.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_en.lproj_iPodServiceLocalized.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_es.lproj_iPodServiceLocalized.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_fi.lproj_iPodServiceLocalized.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_fr.lproj_iPodServiceLocalized.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_it.lproj_iPodServiceLocalized.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_ja.lproj_iPodServiceLocalized.dll
Cleaned
C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.3.2.6\iTunes.msi=>(Embedded CAB)=>iPodService.Resources_ko.lproj_iPodServiceLocalized.dll
Cleaned